We often talk about steps that can be taken to reduce the risk of data breaches, and cyber attacks in particular; but what if the worst happens? What can you do to help recover from an attack like this?
The National Cyber Security Centre has addressed this in some recently issued guidance, which covers:
- Things you should do straight away – such as establishing a command structure, reporting to the NCSC and other regulators, considering shut down/disconnection of systems etc.
- The recovery programme in the first few days and weeks – the aim of this stage is to reduce harm from the incident and recover the organisation to a level of minimum viable operations
- The rebuilding phase when the crisis has passed – this stage focusses on building back to normal capacity and looking forward to strengthen resilience
You can find the full guidance here.